PT-2023-28372 · Zavio · Zavio Cb3211+10

Attila Szasz

+1

·

Published

2023-09-07

·

Updated

2024-08-02

·

CVE-2023-4249

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Zavio CF7500, CF7300, CF7201, CF7501, CB3211, CB3212, CB5220, CB6231, B8520, B8220, and CD321 with firmware version M2.1.6.05
Description The issue is related to a command injection vulnerability in the implementation of binaries and handling of network requests in the affected IP cameras.
Recommendations For Zavio CF7500, CF7300, CF7201, CF7501, CB3211, CB3212, CB5220, CB6231, B8520, B8220, and CD321 with firmware version M2.1.6.05, consider disabling the handling of network requests until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

OS Command Injection

Stack Overflow

Weakness Enumeration

Related Identifiers

CVE-2023-4249

Affected Products

Zavio B8220
Zavio B8520
Zavio Cb3211
Zavio Cb3212
Zavio Cb5220
Zavio Cb6231
Zavio Cd321
Zavio Cf7201
Zavio Cf7300
Zavio Cf7500
Zavio Cf7501